The BuleHero botnet was seen using multiple modules to move laterally on a network and increase the spread of its two payloads, the XMRig miner and the Gh0st remote-access Trojan (RAT) ZScaler observed the threat sequentially scanning for IP addresses with ports 80 and 3389 open. Security professionals can help their organizations defend against the botnet by leveraging user behavior analytics (UBA) to identify patterns that could point to potentially malicious behavior on the network.”]

